Former U.S. Army soldier Cameron John Wagenius, known online as kiberphant0m, was sentenced to 70 months in federal prison and ordered to pay $294,978 in restitution for hacking, data theft and extortion targeting telecommunications companies and other organizations. Prosecutors said Wagenius and co-conspirators obtained credentials for at least 10 victims between April 2023 and December 2024, stole and sold sensitive data, demanded ransoms, and used records in SIM-swapping fraud. He pleaded guilty to wire-fraud conspiracy, computer-fraud-related extortion, aggravated identity theft, and unlawful transfers of confidential phone records.
While stationed at Fort Cavazos, Wagenius used the credential-stealing tool SSH Brute, which he helped develop, and collaborated with Connor Moucka and alleged co-conspirator John Erin Binns. The operation was tied to the Snowflake customer-data theft wave, in which stolen credentials and accounts lacking multifactor authentication enabled theft of billions of records, including call and text metadata affecting more than 100 million AT&T customers. AT&T paid a $370,000 Bitcoin ransom; the group later posted purported call logs for Donald Trump and Kamala Harris and alleged NSA schematics. Wagenius also allegedly tried to sell stolen data to a foreign intelligence service and, while awaiting sentencing, sought exploit and escape-related guidance through other inmates' email accounts; authorities said they found no evidence he compromised Bureau of Prisons systems.

See the reporting duties and controls this puts on the clock.
12 events from the most recent confirmed update back to the earliest known activity.
While awaiting sentencing, Wagenius allegedly used other inmates' email accounts to seek AI-generated Windows privilege-escalation guidance, exploit code for CVE-2023-45208, prison antenna advice, and prison-escape research. The government said it found no evidence he used or deployed vulnerabilities against Bureau of Prisons systems.
Moucka pleaded guilty to a central role in compromising more than 165 Snowflake customer environments and enabling large-scale theft used for extortion.
Wagenius pleaded guilty to wire-fraud conspiracy, computer-fraud-related extortion, aggravated identity theft, and related hacking and data-theft offenses.
Canadian national Connor Moucka was extradited to the United States in connection with the Snowflake customer-environment compromises.
Federal authorities arrested Wagenius, finding thousands of stolen identification documents and substantial cryptocurrency holdings on seized devices. Following the seizure, he acquired a new laptop despite an order from his commanding officer not to do so and used it in barracks at Fort Cavazos.
Wagenius published two posts disclosing confidential call records belonging to a government official and relatives of a former official, while threatening to release further records unless ransoms were paid. Accounts attributed to him also posted purported call logs associated with Donald Trump and Kamala Harris.
An account using Wagenius's Kiberphant0m alias claimed it had stolen call and text metadata for tens of millions of AT&T customers, including phone numbers, timestamps, and call durations.
AT&T disclosed that attackers had stolen call and text records for nearly all of its cellular customers over a six-month period in 2022 from its Snowflake account.
Conor Riley Moucka, also known as Judische, was arrested in connection with the Snowflake customer data thefts.
Between April 2023 and December 2024, Cameron John Wagenius and associates obtained credentials for at least 10 organizations. They used SSH Brute and stolen credentials to access cloud environments, steal data, demand ransoms, sell data, and conduct SIM-swapping-related fraud.
Attackers stole six months of call and text records involving nearly all AT&T cellular customers from AT&T's Snowflake account during 2022.
A federal court sentenced former Army soldier Cameron John Wagenius to 70 months in prison for the cyberattack and extortion campaign and ordered him to pay approximately $294,978 in restitution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcekrebsonsecurity.com
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.